-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi Onno,

On Fri, 6 Jun 2014 08:47:32 +0200, Onno Ekker wrote:
> Hi,
> 
> Yesterday another OpenSSL was published: 
> https://www.openssl.org/news/secadv_20140605.txt
> 
> Along with it the security advisory came a fix for servers.
> 
> Enigmail is using GPG, which probably uses OpenSSL, so i think it's
> also vulnerable to this issue?
> 
> Which versions of GPG are affected and is there a fix for this on
> the client side? The vulnerability only works if both the client
> and the server are vulnerable, so if we can fix this on the client
> side, we should be safe for all servers, independent of their
> state...
> 
> I haven't find about it, and it's probably more a case for a GPG
> group, but I'm not subscribed to a GPG group, that's why I ask it
> here.
> 
> Onno

GPG itself does not contains any OpenSSL components because OpenSSL
License is not compatible with GPL.

There is a possibility that some libraries or components use OpenSSL.
It depends on your system.

ex. Gpg4win (gpg2 package for Windows) does not contain OpenSSL.
http://lists.wald.intevation.org/pipermail/gpg4win-users-en/2014-April/000962.html
http://lists.wald.intevation.org/pipermail/gpg4win-users-en/2014-April/000963.html

I think it is better to ask on GnuPG mailing lists.

- -- 
Kosuke Kaizuka <[email protected]>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (MingW32)

iQIcBAEBCgAGBQJTkYoLAAoJEFI91dNOjkjZwTcQAJjX0rttqAlWUDcs1Gn6wg2x
Ot3ZuXqprt0SMMkunKibUwDHWsZXBGvkMR9/1BezEhh7DohgCocwwEwzMXoUtMvZ
5HRRDtwj4x9CfpPjo5jUeLqoj1MWsolrWgW0Z+/EzjasZqjf1Q75DgBZCIZF8UVP
Q0AdW+Dkf2ergvSOT6A5wQ9GLRwc3MElbEJkHx4nOhcDdquFvIE0+kxz/prbp61W
X6j1H/SbR3Pa/WVVUc+baoZw0RJ+40wZwqk8AgTRIgIVZ/Ac7a5D1O/A+8DbMj9s
B0DNenNatcxjMCq/7VbpiMGpgU6J1jqLaBahNP36+W9E7fA7Joc7OMtRlnFq9UXa
iQQyat8bsx6L/NsLa34me/koLTbyZ1JnYMsAxJSV72Te10saE2xpp4mCdPFivV5R
bbZt+3LkxCWJTnqxk2PjW//lIGkYQeQ9OZyCg7cj+5xtzN3fVlb0M60IUKCmUERB
cmIp6tSpNVeDc4owUe63aQrI2hmuWLmcRVQ/pQm918rGFG7uZHn/KVMDaoygCCq7
9YzEmXjpc0/jeUdOvJQjJIyzgaJVIEwtXbtRDJxSngWr0FzYParHkXwDsdEnn6Ne
WeIWKsP5m4VzyJAREjXQpgk00pGzvTr6o0qAH7mPVCzzus8zd3pDJb1QI33ylDnM
nmrST2XYPnYgiO4wbfYl
=9ZRJ
-----END PGP SIGNATURE-----

_______________________________________________
enigmail-users mailing list
[email protected]
https://admin.hostpoint.ch/mailman/listinfo/enigmail-users_enigmail.net

Reply via email to